CVE-2026-16908
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path trav
CVSS
8.5
High
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Published: Aug 13, 2026 · Last modified: Aug 17, 2026 · CWE-22
0.4%EPSS · 30 days0.4%
2026-08-252026-09-23
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain unauthorized access to arbitrary objects due to a path traversal vulnerability.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-955256.5 MED—
——0Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions.3hCVE-2026-966516.5 MED—
——0Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.5hCVE-2026-962769.8 CRI—
——0If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak build-init --writable-sdk --sdk-extension` with that SDK, attacker-chosen files could be written outside the working directory, since the target path is resolved via a function that allows `..` traversal.3hCVE-2026-962758.8 HIG—
——0A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host filesystem via extract_extra_data(). On system installs, the write happens as root. Two issues combine: `files/extra` is resolved via path operations that follow symlinks, and blob names from `xa.extra-data-sources` are not sanitized against `..` traversal.3hCVE-2026-918017.8 HIG11.1%
——3A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.5hCVE-2026-194387.5 HIG35.1%
——11Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I.
This issue affects Mint Workbench I: through 5876.5h